CVE-2011-3482: Medium severity wireshark vulnerability
An uninitialized variable flaw was found in the CSN.1 dissector of wireshark. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This affects versions 1.6.0 to 1.6.1 and has been fixed in version 1.6.2
Reference: http://www.wireshark.org/security/wnpa-sec-2011-16.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Other sources
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3482?
CVE-2011-3482 is considered a medium severity vulnerability that can lead to application crashes.
How do I fix CVE-2011-3482?
To fix CVE-2011-3482, upgrade Wireshark to version 1.6.2 or later.
Which versions of Wireshark are affected by CVE-2011-3482?
CVE-2011-3482 affects Wireshark versions 1.6.0 and 1.6.1.
What causes CVE-2011-3482 in Wireshark?
CVE-2011-3482 is caused by an uninitialized variable flaw in the CSN.1 dissector.
Can CVE-2011-3482 be exploited remotely?
Yes, CVE-2011-3482 can potentially be exploited by injecting a malformed packet onto the wire.